CVE-2026-82535
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Summary
Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by computing deterministic invitation codes and bypassing authorization checks in the survey submission endpoint. Attackers can submit crafted answers containing unescaped HTML rendered in reporting views to execute arbitrary scripts in the browser sessions of teachers or administrators, enabling persistent backdoor account creation by exploiting the victim's authenticated session.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| chamilo | chamilo-lms | 1.11.0 <= 1.11.40 | affected |
| chamilo | chamilo-lms | 2.0.0 <= 2.0.3 | affected |
| chamilo | chamilo-lms | 1.11.42 | unaffected |
| chamilo | chamilo-lms | 3.0.0 | unaffected |
Weaknesses
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-m3wr-p8wj-jmf6
- https://github.com/chamilo/chamilo-lms/releases/tag/v3.0.0
- https://github.com/chamilo/chamilo-lms/commit/be45f2f2a29319afbbf9ce27d094698911799d10
- https://github.com/chamilo/chamilo-lms/commit/c9d2614d798571b94cef1cb61e605a2fc89f0386
- https://github.com/chamilo/chamilo-lms/commit/bea9cbcfc6ca58f387c6c25bef2f15dc5df9d147
- https://www.vulncheck.com/advisories/chamilo-lms-stored-xss-via-survey-answer-submission-in-reporting-php
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.